Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

CVE-2025-11262 is a stored cross-site scripting vulnerability in the Link Whisper Free WordPress plugin, affecting all versions up to and including 0.9.0. Unauthenticated attackers can inject malicious scripts that are stored server-side and executed in the browser of every visitor to affected pages, putting all site visitors at risk of session hijacking and credential theft. Organizations running this plugin on public-facing WordPress installations should treat this as a priority remediation item.

Author

Tech Jacks Solutions